cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
497
Views
0
Helpful
3
Replies

ESA file analysis (AMP) lost emails

Hello community, 

we have HW cisco with HW Threat grid integration. The problem that we have is when the file is send for analysis the message is quarantined in File quarantine. I checked that the Threat grid needs 5-10 min to finish the analysis, after that I can`t see the message in quarantine and it is not delivered to recipient.  The retention period expired and the action is Release.  Where could it have gone ?

3 Replies 3

Pulkit Mittal
Spotlight
Spotlight

Have you checked the message tracking, if it didn't get delivered then I think it hit another quarantine filter. If the message tracking says delivered then also verify O365 message trace.

If you find this useful, please mark it helpful and accept the solution.

I checked the message tracking and quarantines and it is not their. We don`t have 0365 integration. 

saliyev
Cisco Employee
Cisco Employee

do you use centralized quarantine by SMA?
the message could stuck in delivery queue of SMA (check it by tophosts and showrecipients command on SMA CLI)
and/or need to trace one sample message by mail logs which might be helpful.